PT-2026-60258 · Pypi · Strands-Agents-Tools
CVE-2026-15746
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
strands-agents-tools versions prior to 0.7.0
Description
A server-side request forgery (SSRF) issue exists in the elasticsearch memory tool of the strands-agents-tools package. The tool exposes connection parameters
es url, cloud id, and api key as fields controllable by the large language model (LLM) via the tool schema. If the api key parameter is omitted, the tool uses the operator's ELASTICSEARCH API KEY environment variable and sends it to the host specified by the LLM. A crafted prompt can force the tool to connect to an external server, disclosing the operator's Elasticsearch API key within the Authorization header.Recommendations
Upgrade to version 0.7.0 or later.
Rotate the
ELASTICSEARCH API KEY as a precautionary measure.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Strands-Agents-Tools